课题基金 / 基金详情

TTP: Small: Network-Level Security Posture Assessment and Predictive Analytics: From Theory to Practice

TTP: Small: Network-Level Security Posture Assessment and Predictive Analytics: From Theory to Practice
TTP:小:网络级安全态势评估和预测分析:从理论到实践
批准号:
1616575
负责人:
Mingyan Liu
金额:
$50.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2016
资助国家:
美国
项目状态:
已结题
起止时间:
2016-08-15 至 2021-07-31

项目摘要

项目成果

Mingyan Liu的其他基金

相似基金

相关文献

中文摘要
翻译
该项目解决了网络安全中的以下两个关键问题:(1)如何评估网络的安全状况,以及(2)我们在多大程度上可以预测组织的数据泄露或其他网络安全事件。回答这两个问题的能力具有深远的社会和经济影响。最近发生在塔吉特(Target)、摩根大通(JP Morgan)、家得宝(Home Depot)、人事管理办公室(Office of Personnel Management, OPM)和安森医疗(Anthem Healthcare)的数据泄露事件,凸显了此类网络安全事件对社会和经济的影响越来越大。通常,当发现违规行为时,为时已晚,损害已经发生。因此,能够准确地预测此类事件可以大大提高组织将预防和主动措施放在适当位置的能力。这些问题的答案对公共政策设计也有影响——不仅对安全政策本身,而且对相关的激励机制也有影响。这些机制可能旨在鼓励采用更好的安全政策和网络安全框架,包括网络保险、责任限制和费率回收等。总统政策指令(PPD) 21,关于关键基础设施安全和弹性,鼓励努力加强和维护安全,功能和弹性的关键基础设施。了解企业或组织提供的潜在攻击向量是实现这一目标的关键部分。该项目遵循一个全面的议程,旨在过渡到由研究团队在网络和组织级别的安全态势定量评估领域开发的实践技术。使用此类评估可以更准确地预测网络安全事件。技术创新是一个健全的定量框架,结合了大量的网络安全数据、新颖的数据处理方法、先进的机器学习技术和广泛的网络安全领域专业知识。由此产生的框架为给定的组织生成安全事件的准确预测,从而为决策者(如保险承保人或寻求验证供应商规范的企业客户)提供切实的信息和关键的输入。
英文摘要
This project addresses the following two key questions in cyber security: (1) how is the security condition of a network assessed, and (2) to what extent can we predict data breaches or other cyber security incidents for an organization. The ability to answer both questions has far-reaching social and economic impact. Recent data breaches such as those at Target, JP Morgan, Home Depot, Office of Personnel Management (OPM), and Anthem Healthcare, to name just a few, highlight the increasing social and economic impact of such cyber security incidents. Often, by the time a breach is detected, it is too late and damage has already occurred. Consequently, being able to predict such incidents accurately can greatly enhance an organization's ability to put preventative and proactive measures in place. The answers to these questions also have implications on public policy design - not only for the security policies themselves, but also for related incentive mechanisms. Such mechanisms might be aimed at encouraging adoption of better security policies and cybersecurity frameworks, including cyber insurance, liability limitation, and rate recovery among others. Presidential Policy Directive (PPD) 21, on Critical Infrastructure Security and Resilience, encourages efforts to strengthen and maintain secure, functioning, and resilient critical infrastructure. Understanding the potential attack vector presented by an enterprise or organization is a crucial part of achieving this goal.This project follows a comprehensive agenda aimed at transitioning to practice technologies developed by the research team in the domain of quantitative assessment of the security posture at both a network and an organizational level. The use of such assessments enables more accurate forecasting of cyber security incidents. The technological innovation is a sound quantitative framework that combines a large collection of cybersecurity data, novel data processing methods, advanced machine learning techniques, and extensive cybersecurity domain expertise. The resulting framework produces accurate predictions of security incidents for a given organization, thereby providing tangible information and crucial input for decision makers such as an insurance underwriter, or an enterprise customer seeking to validate vendor specifications.
期刊论文(5)
专著(0)
科研奖励(0)
会议论文
DOI: 10.1145/3446635
发表时间: 2021
期刊: ACM Transactions on Management Information Systems
影响因子: 2.5
作者: [Pal, Ranjan, Huang, Ziyuan, Lototsky, Sergey, Yin, Xinlong, Liu, Mingyan, Crowcroft, Jon, Sastry, Nishanth, De, Swades, Nag, Bodhibrata]
通讯作者: Nag, Bodhibrata
Preference-Based Privacy Markets
基于偏好的隐私市场
DOI: 10.1109/access.2020.3014882
发表时间: 2020
期刊: IEEE Access
影响因子: 3.9
作者: [Pal, Ranjan, Crowcroft, Jon, Wang, Yixuan, Li, Yong, De, Swades, Tarkoma, Sasu, Liu, Mingyan, Nag, Bodhibrata, Kumar, Abhishek, Hui, Pan]
通讯作者: Hui, Pan
Aggregate Cyber-Risk Management in the IoT Age: Cautionary Statistics for (Re)Insurers and Likes
物联网时代的总体网络风险管理:(再)保险公司和类似机构的警示统计数据
DOI: 10.1109/jiot.2020.3039254
发表时间: 2021
期刊: IEEE Internet of Things Journal
影响因子: 10.6
作者: [Pal, Ranjan, Huang, Ziyuan, Yin, Xinlong, Lototsky, Sergey, De, Swades, Tarkoma, Sasu, Liu, Mingyan, Crowcroft, Jon, Sastry, Nishanth]
通讯作者: Sastry, Nishanth
DOI: 10.1109/tifs.2018.2812205
发表时间: 2018-03
期刊: IEEE Transactions on Information Forensics and Security
影响因子: 6.8
作者: [Mohammad Mahdi Khalili;Parinaz Naghizadeh;M. Liu]
通讯作者: Mohammad Mahdi Khalili;Parinaz Naghizadeh;M. Liu
EAGER: Theory and Practice of Risk-Informed Cyber Insurance Policies: Risk Dependency, Risk Aggregation, and Active Threat Landscape
CPS:Small:Collaborative Research: Incentivizing Desirable User Behavior in a Class of CPS
CI-NEW: Collaborative Research: COVE-Computer Vision Exchange for Data, Annotations and Tools
TWC: Small: Understanding Network Level Malicious Activities: Classification, Community Detection and Inference of Security Interdependence
国内基金
海外基金
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
  • 依托单位:
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    10.0万元
  • 批准年份:
    2022
  • 负责人:
    张祥忠
  • 依托单位:
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
  • 批准号:
    31972324
  • 项目类别:
    面上项目
  • 资助金额:
    58.0万元
  • 批准年份:
    2019
  • 负责人:
    高学文
  • 依托单位: